All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Your public Chess.com profile shows your username, country, and rating. The leaked version reveals something you cannot normally see: how Chess.com sorts you for advertisers.
A 15.5GB file posted on data-leak forums reportedly contains more than 7.3 million Chess.com records.[1] Each one includes internal advertising fields labeled trial eligibility, lapsed users, rating bands, and “coach-nudge” experiments.
Those labels do not appear on your profile or in Chess.com’s public API. There is no obvious setting to review or correct them, either.
That makes this more than another leak story. It offers a rare look at the commercial profile a free platform builds behind the scenes, including what Chess.com appears to have concluded about you.
Chess.com’s hidden advertiser profiles
Can you see what Chess.com knows about you?
Was Chess.com hacked?
What Chess.com users should do now
What was exposed in the Chess.com leak?
The file appeared on two unnamed data-leak forums on August 12, 2026. An analysis of the full dataset found 7,337,395 records, each with 38 fields. The data reportedly included:
- Email addresses
- Usernames, names, and account IDs
- Countries, locations, and language settings
- Chess titles, ratings, and skill levels
- Premium membership details
- Account creation and recent login dates
- Internal advertising labels
About 75% of the records contained an email address. However, the leak likely affects fewer than 7.3 million individual players because roughly 7.4% of user IDs appeared more than once.
The data is also recent. It was collected between July 26 and August 3, sometimes capturing the same account on multiple days.
Researchers checked timestamps hidden inside Chess.com-issued account IDs against the registration dates listed in the file. Nearly every one matched, offering strong evidence that the data is real.
Chess.com had not publicly confirmed the leak at the time of writing.
Chess.com’s hidden advertiser profiles
Two fields make this leak particularly revealing: gam_audiences and audiences_member_of. Both reportedly contain Google Ad Manager audience segments, and every record had them filled in. The labels placed players into groups based on factors such as their rating, trial eligibility, or whether they had stopped using the platform.
In other words, Chess.com was sorting players into groups that could shape the promotions, experiments, or sales pitches they received.
Chess.com tells users that it collects plenty of behavioral information. Its privacy policy specifically mentions activity patterns, purchase history, products considered, ratings, club memberships, penalties, and complaints. It also says the company draws “inferences” from the information it collects.
For U.S. advertising, Chess.com says it may sell or share identifiers and online activity with advertising networks, data brokers, and other advertising companies. Its cookie policy also says tracking cookies can build interest profiles using activity on Chess.com and elsewhere online.
That tells you profiling happens. It does not show you the actual labels attached to your account. Agreeing to personalized ads may feel different when you learn you have been placed in a “lapsed-user” group or selected for a behavioral experiment.
Can you see what Chess.com knows about you?
Chess.com says its My Data page lets you view “all the account data” it stores.
However, its help page only specifically mentions information from your settings, mobile device data, and anti-fraud login details. It does not say whether your advertising segments will appear.
The usual privacy controls will not help much, either. They let you manage social features, such as who can challenge you or view your friends list, but not labels like “trial eligible.”
You can limit some targeted advertising by opening Privacy Settings in the Chess.com website footer and turning off Targeting Cookies. According to Chess.com, that’ll stop third-party ads from being personalized based on your interests.
This may not delete labels already attached to your account or affect groups used for Chess.com’s own promotions. The company has not explained how players can inspect, correct, or remove the segments found in the leak.
Depending on where you live, you may also have the right to request your personal information or ask Chess.com to correct/delete it.
Was Chess.com hacked?
The evidence points to automated scraping, rather than a break-in at Chess.com’s main database. Records were gathered in batches over nine days, with some accounts captured more than once — like a program repeatedly collecting data.
Still, one question remains. The internal advertising labels are not available through Chess.com’s public API, yet they appear in every record. The scraper may have reached an authenticated or otherwise non-public interface.
Only Chess.com can explain how those fields became accessible and whether someone bypassed its security controls.
In 2023, someone abused its find-friends feature to link external email addresses to Chess.com accounts. The resulting file contained 828,327 records. Days later, another collection affecting nearly 476,000 users was published.
A separate 2025 breach involving a third-party file-transfer app exposed information belonging to 4,541 people.
What Chess.com users should do now
There is no evidence that this leak contains passwords or anything else that would let someone sign in to your account. Resetting your password will not remove your information from the file.
The big concern here is phishing. A scammer who knows your account details could write a convincing message about a subscription renewal, tournament invitation, etc.
Avoid login links in unexpected emails. Open Chess.com through its app or type the address into your browser instead. Chess.com will not need your password or authentication code to investigate your account.
You should still use a unique password and enable two-factor authentication. This will protect you if the same email address appears in another leak that includes login credentials.
Finally, check Chess.com’s My Data page. If it does not show the advertising fields, you may be able to contact the company and request a complete copy of the personal information and inferences attached to your account.
This leak reveals the quiet bargain behind a free account: While you build a chess rating, the platform may be building an advertising rating of its own.